cvelist/2019/18xxx/CVE-2019-18341.json

71 lines
2.5 KiB
JSON
Raw Normal View History

{
"CVE_data_meta": {
"ASSIGNER": "productcert@siemens.com",
"ID": "CVE-2019-18341",
"STATE": "PUBLIC"
},
"data_format": "MITRE",
"data_version": "4.0",
"data_type": "CVE",
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Siemens AG",
"product": {
"product_data": [
{
"product_name": "SiNVR 3 Central Control Server (CCS)",
"version": {
"version_data": [
{
"version_value": "all versions"
}
]
}
},
{
"product_name": "SiNVR 3 Video Server",
"version": {
"version_data": [
{
"version_value": "all versions"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-287: Improper Authentication"
}
]
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The SFTP service (default port 22/tcp) of the SiNVR 3 Central Control Server\n(CCS) contains an authentication bypass vulnerability.\n\nA remote attacker with network access to the CCS server could \nexploit this vulnerability to read data from the EDIR directory\n(for example, the list of all configured stations).\n"
}
]
},
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-761617.pdf"
}
]
}
}